Security

 View Only
last person joined: 23 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Printers with MAC-Auth disappears and lose connectivity

This thread has been viewed 43 times
  • 1.  Printers with MAC-Auth disappears and lose connectivity

    Posted Mar 27, 2023 03:54 AM

    Hi.

    I am using MAC authentication for Printers in my organization.

    My rule is: If the printer's MAC is known and another attribute I added manually to each printer: "Endpoint:Device-Type = Printer" exists, Then send some user-role (That is configured on the switch).

    Things are working fine but after a day, some of the printers "disappear" and only shutting down the port and bringing it back, makes them get back.

    Any ideas on how I can solve this issue?



    ------------------------------
    Best regards,
    Alon Haber
    ------------------------------


  • 2.  RE: Printers with MAC-Auth disappears and lose connectivity

    Posted Mar 27, 2023 04:09 AM
    Hi,

    Could you elaborate more on the 'disappear' ?
    Does it mean the printer lose connectivity, or only the logs in Access Tracker disappears ?

    Do u set any session timeout enforcement profile in the clearpass to send back into the switch/wlc ? Or maybe u hv default session timeout in the authenticator (sw/wlc) itself.
    But why disappear... I need to know first what u mean by disappear.





  • 3.  RE: Printers with MAC-Auth disappears and lose connectivity

    Posted Mar 27, 2023 05:49 AM

    Yes,

    It means printers lose connectivity.

    If I go into the switch, There is no MAC on the port. And under "Show port-access clients" there is no entry for the specific printer.

    If I shutdown the port and bring it back up, It would see the printer again. 



    ------------------------------
    Best regards,
    Alon Haber
    ------------------------------



  • 4.  RE: Printers with MAC-Auth disappears and lose connectivity

    Posted Mar 27, 2023 04:21 AM

    Are the printers going into sleep mode? Have you tested with one printer to disable sleep mode and test the next day if it's still available?




  • 5.  RE: Printers with MAC-Auth disappears and lose connectivity

    Posted Mar 27, 2023 05:47 AM

    I didn't know there is an option to the printer to fo to sleep mode.

    But even if it does. The only way is to disable sleep mode ?



    ------------------------------
    Best regards,
    Alon Haber
    ------------------------------



  • 6.  RE: Printers with MAC-Auth disappears and lose connectivity

    Posted Mar 27, 2023 05:52 AM

    It's just to establish if that's the issue as opposed to something wrong with Clearpass or the Switch. I think it's a common issue. 




  • 7.  RE: Printers with MAC-Auth disappears and lose connectivity

    Posted Mar 27, 2023 06:21 AM

    I will disable sleep mode on the printers and try again to authenticate.

    Thank you.



    ------------------------------
    Best regards,
    Alon Haber
    ------------------------------



  • 8.  RE: Printers with MAC-Auth disappears and lose connectivity

    Posted Mar 28, 2023 01:55 AM

    This link will describe best what you are experiencing.

    I have the same issue and for now I added to the switch port this command (ArubaOS) which seems to solve it.

    aaa port-access controlled-direction in

    although i still don't fully understand what downsides this command has.




  • 9.  RE: Printers with MAC-Auth disappears and lose connectivity

    Posted Apr 04, 2023 05:05 PM

    This is the answer. Have run into this a few times.

    "aaa port-access controlled-direction in" essentially means only apply policy / authenticate traffic coming "in" the port. If the printer goes to sleep, a packet destined for it can still be sent out the port to wake it up. Once it awakens you should see a new auth in your RADIUS server.



    ------------------------------
    ACNSA | ACEA | ACCP | ACMP
    ------------------------------



  • 10.  RE: Printers with MAC-Auth disappears and lose connectivity

    Posted Mar 28, 2023 03:25 AM

    Hi Alon,
    what type of Switches do you use?

    In case you use AOS (Procurve) you might want to check the logoff-period setting: i.e. aaa port-access authenticator 1 logoff-period 864000

    In case you use AOS CX (Aruba CX) you might want to check client inactivity timout in the local access role settings

    Kind regards

    Martin



    ------------------------------
    Martin
    ------------------------------



  • 11.  RE: Printers with MAC-Auth disappears and lose connectivity

    Posted 3 days ago

    Hi all,

    I ran into the same problem with a Lexmark printer (Lexmark Firmware, Magazine = LW50.PR2.P544-0, Kernel = FW5.CY.F544-0, Base = LW50.PR2.P544-0, Network = NH5.CY.N543-0, Network Driver = LW50.PR2.P544-0, Engine = FDN.PIR.E618-0).
    In the CX series switches no problem, in the procurve series switches, however, after about 10 minutes of inactivity the printer no longer responds.

    This is the configuration:

    aaa accounting update periodic 3
    aaa accounting network start-stop radius
    aaa authentication login privilege-mode
    aaa authentication ssh login radius local
    aaa authentication ssh enable radius local
    aaa authentication port-access eap-radius

    aaa port-access authenticator 1

    aaa port-access authenticator 1 client-limit 1

    aaa port-access authenticator active

    aaa port-access mac-based 1

    aaa port-access mac-based 1 logoff-period 99999

    Do you have any ideas?

    With the CX switches and the printer itself the problem does not arise.

    Thanks 



    ------------------------------
    carabina5
    ------------------------------



  • 12.  RE: Printers with MAC-Auth disappears and lose connectivity

    EMPLOYEE
    Posted 2 days ago

    You may have a look at the mac-pinning feature in ArubaOS Switch (Provision/Procurve based).



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------